OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Cannot Connect To Network Switch From LAN
« previous next »
  • Print
Pages: 1 [2]

Author Topic: Cannot Connect To Network Switch From LAN  (Read 610 times)

run('Jimbo');

  • Newbie
  • *
  • Posts: 21
  • Karma: 0
    • View Profile
Re: Cannot Connect To Network Switch From LAN
« Reply #15 on: October 27, 2024, 09:59:12 am »
Sorry, I don't understand what you mean?

I have 4 vlans on igb1 working well...

Thanks
Logged
Jimbo.

    OPNsense 24.7.7
------------------------

EricPerl

  • Full Member
  • ***
  • Posts: 109
  • Karma: 4
    • View Profile
Re: Cannot Connect To Network Switch From LAN
« Reply #16 on: October 27, 2024, 08:39:16 pm »
Quote from: run('Jimbo'); on October 26, 2024, 03:58:27 pm
...
Interface LAN        (igb0); 10.34.1.0/24
Interface SWITCH  (igb1); 10.34.2.0/24 -> NETGEAR MANAGED SWITCH static 10.34.1.50
...

Maybe it's a terminology issue (it could be on my side too), but when I read the above, I only see 1 network/subnet per physical interface.
You had mentioned VLANs earlier in this thread, but not how they were configured (and nobody asked because it seemed irrelevant since we were only dealing with native networks).
You probably have your reasons for creating that 2nd network. I'll leave it at that...

AFAIK, VLANs have no access to the underlying native network by default.
In fact, by default, they don't seem to have access to anything.
Logged

run('Jimbo');

  • Newbie
  • *
  • Posts: 21
  • Karma: 0
    • View Profile
Re: Cannot Connect To Network Switch From LAN
« Reply #17 on: October 27, 2024, 11:50:41 pm »
Quote from: run('Jimbo'); on October 26, 2024, 08:10:18 pm
I want to separate my vlans and switch from igb0 because it's allow all by default. If I move over to igb1 I can block all on igb1 and ony allow what is needed on the vlan interfaces...

LAN should have access to all regardless???

Thanks
Logged
Jimbo.

    OPNsense 24.7.7
------------------------

EricPerl

  • Full Member
  • ***
  • Posts: 109
  • Karma: 4
    • View Profile
Re: Cannot Connect To Network Switch From LAN
« Reply #18 on: October 28, 2024, 07:55:01 pm »
Yes, I saw this. I guess my initial statement about VLANs should not have been about existence but relevance.

I merely wanted to make sure you understood that the physical isolation (LAN vs SWITCH) is orthogonal to the isolation you want from your VLANs, regardless of their parent interface.
By default, LAN gets a ANY to ANY rule (you can change it, override it...).
SWITCH got nothing by default. You may have given it access to the Internet but apparently not LAN (devices off the switch in the SWITCH native subnet can't reach LAN).
VLANs (regardless of parent interface) get nothing by default either. You decide what to allow, independently of the parent interface.
At least that's my experience...
Logged

  • Print
Pages: 1 [2]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Cannot Connect To Network Switch From LAN
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2